In 2002, I was the Network Security Officer at the US Naval Postgraduate School in Monterey. Every computer on our network had a public IP address that could be attacked from anywhere in the world. There were no firewalls in front of those machines. There was no procedure for pushing patches to them. Plenty of them were running antivirus signatures that had not been current for months. (If you are new to this craft and that paragraph reads like a confession, understand: in 2002, that was a normal network.)
When Blaster came to Monterey
Microsoft shipped the patch for the DCOM RPC vulnerability (MS03-026) on 16 July 2003. Twenty-six days later, the Blaster worm arrived and wrecked those machines. My team, all of IT, and anyone on campus who had ever installed RAM got deputised into rebuilding hundreds of infected computers. Not cleaning. Rebuilding. It is the kind of week that permanently rearranges your opinions about prevention.
Seventeen days
Nine months later came the sequel. On 13 April 2004, Microsoft published MS04-011, patching the LSASS vulnerability, and working exploit code was circulating publicly within two weeks. I knew we were on a ticking clock (I have been grumpy about the shrinking patch window for a long time; see Day Zero Is How Long??!). I was frustrated by the lack of action on firewalls and patch management, so I went vigilante and did it myself. I patched every machine I had credentials for. Then I wrote a program that scanned our network space for computers still vulnerable to the exploit, used the exploit to get on the box, and applied the patch. A benevolent attack, if you are feeling generous about it. (I had the job title to defend it. Barely.)
Seventeen days after the bulletin, Sasser hit. Aside from one research machine that broke on a bug in my benevolent attack, the network was spared another round of wipes and rebuilds.
The teenagers behind the worms
Here is the part worth remembering about Blaster and Sasser: they were not nation-state operations. Whoever wrote the original Blaster was never identified. The code carried a taunt aimed at one man ("billy gates why do you make this possible? Stop making money and fix your software!!") and pointed its infected drones at windowsupdate.com, a denial-of-service attack on the very site serving the fix. The one arrest that followed was Jeffrey Lee Parson, an 18-year-old from Minnesota who modified the worm into the Blaster.B variant, infected roughly 7,000 machines, and served 18 months for it.
Sasser was Sven Jaschan, a German student who wrote it at 17 and released it within a day of turning 18. His friends turned him in to collect on Microsoft's US$250,000 bounty. He confessed, was tried as a juvenile, and walked with a 21-month suspended sentence and 30 hours of community service. His motive, per the court coverage, was recognition as a programmer (reportedly with a hoped-for side benefit of drumming up work for his mother's PC repair business). He also wrote Netsky, which he cast as a good-guy worm at war with the Mydoom and Bagle botnets. A security company hired him a few months after the trial.
Teenagers. Clever, bored, working entirely from published vulnerabilities and published exploit code, with no novel tradecraft between them. Our craft had a name for that: script kiddies.
The report I pulled this morning
Twenty-four years after I stood in front of that firewall-less network, it seems insane not to have firewalls, patch programmes, and endpoint protection. Which brings me to the chart.

This is one day of attack flow against WitFoo's own network: 115 breach attempts. 16 of them were driven by AI agents. The rest were mostly plain old data-theft attempts arriving from everywhere and nowhere (71 of the sources hid their origin; the remainder announced themselves from Germany, Iran, India, Brazil, Colombia, and a handful of other places). As I write this, 98 of the 115 are already marked disrupted, and the other 17 are still being worked (16 open, one brand new). The count of successful breaches is zero.
Why the AI is not winning
So why is the AI not finding success? Here's the thing: basic hygiene is just as effective against "agentic" attacks as it was against the teenagers of the 2000s.
Back in 2004 I could have beaten Sasser three separate ways: patch the machine, put a firewall in front of it, or run endpoint protection on it. We call this defence-in-depth because an attacker has to win at every step of the attack path, while a defender only needs to win once, anywhere along the chain. That asymmetry did not expire when the attackers stopped being teenagers and started being GPUs. What did change is volume and tempo: they get a countless number of attempts now, and they can launch them faster than ever. Quantity went up. Quality did not.
All the data we see at WitFoo says the agentic attacks are no more innovative or novel than the script kiddie attacks that preceded them. AI attack traffic, like so much of the content AI creates, is an unimaginative derivative of what already exists. It is slop. Jaschan's worm was at least handcrafted slop; the new stuff is derivative at machine speed. Cybersecurity's newest script kiddies do not have acne and a grudge against Bill Gates. They have a token budget.
More to patch than ever
None of this means the patching job got smaller. I sat down recently to watch Star Trek and had to patch my TV, my Fire TV Cube, and my Plex app before I could "go where no one has gone before." The patch surface of an ordinary life is enormous now, and a programme that was weak at patching before agentic AI has that weakness magnified.
Back in April, when Anthropic's Mythos announcement had a lot of us doing arithmetic on the ceiling at 2am, I wrote Blaster, Mythos, and the Patching Tempo We're About to Need and committed us to a daily patch cadence (a patch stand up, in practice: every morning, every machine, no exceptions). I said at the time I was not panicking. That was about half true. I got as wrapped up in the FUD as anyone. Four months of data later, the honest scorecard: whatever the models can do in a lab is Anthropic's claim to defend, but the catastrophe has not shown up in our data or our customers' data. As breach waves go, it has been a nothing burger. The daily patch cadence, though? We are keeping it. Right move, wrong-sized fear.
The rock and the waves
In 2017, with the help of the University of Chicago, we discovered that more than 99% of attacks in modern networks are disrupted by defence-in-depth controls before they do damage. Most months, the number is 100%. Marcus Aurelius had the image right two thousand years early: "To be like the rock that the waves keep crashing over" (Meditations, Book Four). The network is the rock. The attacks are the waves. The waves are relentless, and the rock mostly does not notice.
You do not have to take my word for it. In the 114-million record dataset we released on Hugging Face this year (live telemetry from five US enterprises, labelled), you will notice the same shape: the attacks never stop, confirmed-malicious activity is a rounding error (0.11% of records), and solid controls beat persistent, unrelenting attackers. The data we have reviewed over the last 12 months shows exactly one thing changing since the AI agents showed up: the number of impotent attacks went up.
The gold rush I am not buying
Billions of dollars are being poured into the promise that an "agentic SOC" is the only possible answer to the agentic attacker. Torq raised US$140 million at a US$1.2 billion valuation on that thesis. Exaforce landed US$75 million to put AI agents in the SOC, and the funding map grows monthly. That said, I have no quarrel with those teams, and some of that tooling will find honest work (I have made my own peace with AI at the right layer of the stack). But the premise underneath the pitch (that the new attackers are so novel we must abandon the playbook that has been winning since 2004) is nonsense. We did not need trick plays then. We do not need them now. Fight slop with fundamentals, not with more slop. (For the longer version of my prevention sermon: An Ounce of Prevention is Worth a Pound of SOAR.)
Wrap Up
My advice is the same as it was in 2002: defence-in-depth, with an effective patch management programme in the middle of it. Review your controls. Patch your machines. Use common sense when you assess your readiness. That is what stopped a teenager's worm in 2004, and it is what stopped 115 breach attempts on my network yesterday, 16 of them run by machines that never sleep.
This post continues the argument of The Closing Window series, and I will own the update honestly: the window moved, and the fundamentals held. The attackers got faster, cheaper, and more numerous, and they are still losing to a patch schedule. We do not need a new religion. We need to do the same things we were doing back when I still had a full head of hair. Sit with that a moment. Then go check when your TV last updated itself.